CVE-2025-53609
- EPSS 0.07%
- Veröffentlicht 09.09.2025 13:50:41
- Zuletzt bearbeitet 10.09.2025 15:14:32
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via craft...
CVE-2025-47857
- EPSS 0.04%
- Veröffentlicht 12.08.2025 19:00:05
- Zuletzt bearbeitet 15.08.2025 12:25:37
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or comman...
CVE-2025-27759
- EPSS 0.04%
- Veröffentlicht 12.08.2025 18:59:49
- Zuletzt bearbeitet 14.08.2025 01:21:25
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated...
CVE-2025-52970
- EPSS 0.48%
- Veröffentlicht 12.08.2025 18:59:25
- Zuletzt bearbeitet 15.08.2025 12:26:38
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the devi...
CVE-2025-32766
- EPSS 0.02%
- Veröffentlicht 12.08.2025 18:59:16
- Zuletzt bearbeitet 14.08.2025 01:21:55
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
CVE-2025-25257
- EPSS 40.42%
- Veröffentlicht 17.07.2025 15:10:04
- Zuletzt bearbeitet 21.07.2025 15:01:21
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated atta...
CVE-2025-22254
- EPSS 0.07%
- Veröffentlicht 10.06.2025 16:36:17
- Zuletzt bearbeitet 22.07.2025 21:25:11
An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16 and before 6.4.15, FortiProxy version 7.6.0 through 7.6.1 and before 7.4....
CVE-2025-25254
- EPSS 0.13%
- Veröffentlicht 08.04.2025 14:15:32
- Zuletzt bearbeitet 22.07.2025 21:23:37
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to acc...
CVE-2024-46671
- EPSS 0.06%
- Veröffentlicht 08.04.2025 14:15:31
- Zuletzt bearbeitet 24.07.2025 19:57:38
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin ...
CVE-2024-50565
- EPSS 0.06%
- Veröffentlicht 08.04.2025 14:15:31
- Zuletzt bearbeitet 25.07.2025 15:22:38
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiPro...